CVE-2026-82773: Medium severity CONPROSYS M2M Gateway Series vulnerability
Published Sep 14, 2026
·Updated
Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
Affected Software
2 affected components
CONPROSYS M2M Gateway Series
CONPROSYS M2M Controller Series
Event History
Sep 14, 2026
CVE Published
via MITRE·06:39 AM
Data Sourced
via MITRE·06:39 AM
DescriptionSeverity
Frequently Asked Questions
1
Does exploitation require the attacker to authenticate first?
No privileges are required for the attacker. The vulnerability is network-accessible, but exploitation requires user interaction.
2
Which users are at risk if the issue is exploited?
Logged-in users of the affected products are at risk because arbitrary script can execute in their web browser. The impact includes low confidentiality and integrity impact, with no availability impact indicated.